How Bastion Found argo-cd's Controller Can Reach cluster-admin

CRITICAL · Privilege Escalation — a real finding on the public argo/argo-cd Helm chart.

TL;DR: Rendering argo/argo-cd and scanning it with Bastion surfaced 19 escalation paths to cluster-admin — the headline being the argocd-application-controller ServiceAccount, bound to a ClusterRole granting verbs:[*] on resources:[*]. It doesn't reach cluster-admin; it is cluster-admin. On the same manifests, kube-score produced 107 findings and 0 about RBAC or escalation.

Escalation is a graph problem, not a per-resource checklist: Bastion builds the privilege graph and runs deterministic BFS to cluster-admin, the node, and secrets, citing file:line for every edge. It reports the path; it never walks it. The fix is to replace the wildcard rule with the specific resources the controller reconciles, and to gate pull requests with bastion diff --fail-on-new-path.

Try the analysis yourself · About Bastion